Privacy Policy
Effective 15 September 2026 · Last updated 15 September 2026
The short version
Verloq connects to your Gmail with read-only permission to find subscription receipts and build you a list of what you pay for.
To do that it reads the headers of messages in the window you choose, and reads the full contents of the messages that look like receipts. It does not read the rest.
Your email data is never sold, never used for advertising, and never used to train general-purpose AI models. Disconnect at any time and it is deleted.
1. Who we are
Verloq (“Verloq”, “we”, “us”) operates this service.
For anything in this policy, write to rishikesh.kulkarni88@gmail.com. We are the data controller for the information described here.
2. What we collect
2.1 Account information
When you create an account we store your email address, your name if you give one, and either a hashed password or the identifier returned by your Google or Microsoft sign-in. Passwords are hashed with bcrypt and are never stored or transmitted in readable form.
2.2 Data from your connected mailbox
When you connect a Google account, you grant Verloq the gmail.readonly scope. This permission cannot send, delete, label or modify anything in your mailbox. Using it, Verloq accesses:
- Message headers (subject, sender name and address, and date) for messages in the lookback window you select (7, 30, 60, 90 or 180 days). These are used to decide which messages are likely to be subscription receipts.
- Full message content: the body text of the smaller set of messages identified as likely receipts. On a typical scan this is a few dozen to a few hundred messages out of several thousand examined.
- Attachments on those messages, such as PDF invoices, which are stored so you can retrieve them from your Verloq account later.
Message contents and attachments from messages that are not identified as receipts are not retained.
If you connect a Microsoft account, the equivalent Mail.Read permission is used in the same way.
2.3 Information Verloq creates
From the above, Verloq derives and stores the subscriptions it detects (service name, merchant, amount, currency, billing frequency, renewal date and a confidence score) along with the suggestions it proposes to you and your decisions on them.
2.4 Technical information
Our servers record standard operational logs: request paths, timestamps, response codes and errors. These are used to keep the service running and to diagnose faults.
3. How we use your Google user data
Data obtained from Google APIs is used for exactly one purpose: to identify your recurring subscriptions and present them to you inside Verloq. Specifically, to detect subscriptions and their amounts and renewal dates, to flag likely duplicates, to store the invoices attached to your receipts, and to avoid re-processing messages already examined.
We do not use it to build advertising profiles, to sell or broker data, to train general-purpose or third-party AI models, or for any purpose you have not been shown.
Google API Services Limited Use disclosure
Verloq’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4. Automated processing
Verloq uses Google’s Gemini API to interpret receipt emails, reading a message to extract the service name, amount, currency and billing cadence. The contents of messages identified as receipts are sent to that API for this purpose.
Google provides this API under terms that do not permit using your content to train its general models. We do not send message contents to any other AI provider.
Verloq does not make decisions with legal or similarly significant effects about you. Every subscription it detects is proposed to you for approval before it appears in your list.
5. Who else processes your data
We do not sell your data or share it for advertising. We rely on the following providers to run the service, each handling data only on our instructions:
| Provider | Purpose | Region |
|---|---|---|
| Neon | Database: accounts, detected subscriptions, receipt data | Singapore |
| Railway | Application hosting | Singapore |
| Google Cloud Storage | Storage of invoice attachments | Asia |
| Google Gemini API | Interpreting receipt emails (section 4) | Asia |
| Resend | Account emails: verification codes, notices | Asia |
We may also disclose information where we are legally required to, or to protect our rights or the safety of others.
6. Security
All traffic runs over TLS. Passwords are hashed with bcrypt. Session cookies are HTTP-only and, in production, restricted to HTTPS. Access tokens for your mailbox are held only for as long as the connection is active and are deleted when you disconnect. Invoice files are stored in a private bucket that is not publicly readable.
No system is perfectly secure, and we do not claim otherwise. If a breach affects your data we will notify you and any regulator we are required to, without undue delay.
7. How long we keep things
- While your account is open. Your account details, detected subscriptions and stored invoices are kept so the service works.
- When you disconnect a mailbox. Verloq deletes the stored access and refresh tokens, stops accessing that mailbox, and asks Google to revoke the authorisation so it no longer appears under your account permissions. You can also remove it yourself at any time at myaccount.google.com/permissions.
- When you close your account. Write to rishikesh.kulkarni88@gmail.com. While Verloq is in beta this is done by hand: your account, subscriptions, suggestions, receipt data, stored invoice files and any active session are deleted, your mailbox authorisation is revoked with Google, and we confirm when it is complete. None of it is recoverable afterwards. Operational logs may persist for up to 30 days before rotating out.
You can also clear detected data at any time from within the app without closing your account.
8. Your rights
You may request a copy of your data, ask us to correct it, ask us to delete it, withdraw your consent to mailbox access, or object to a particular use. Write to rishikesh.kulkarni88@gmail.com and we will respond within 30 days.
You can revoke Verloq’s access to your Google account directly at any time at myaccount.google.com/permissions, independently of us.
If you are in the EU or UK. We process your account data to provide the service you have asked for, and to keep it running and secure. Access to your mailbox rests on the consent you give when you connect an account, and you can withdraw it at any time by disconnecting. Your data is stored and processed outside the EEA and the UK. Write to rishikesh.kulkarni88@gmail.com for details of the safeguards that apply to those transfers. Alongside the rights above you may ask us to restrict processing or to port your data, and you have the right to complain to your local supervisory authority.
9. Cookies
Verloq sets one cookie, which keeps you signed in. There are no advertising or third-party tracking cookies.
10. Children
Verloq is not intended for anyone under 18, and we do not knowingly collect their data. If you believe a child has given us information, contact us and we will remove it.
11. Changes
If we change this policy we will update the date at the top. For changes that materially affect how your Google user data is handled, we will notify you by email before they take effect.
12. Contact
Verloq
rishikesh.kulkarni88@gmail.com
This document is a drafting aid, not legal advice. Have it reviewed against the law that applies to you before you publish it.